CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A tester compromises a domain controller and uses Mimikatz to extract the krbtgt account's NTLM hash via a DCSync attack. The tester then forges a Kerberos ticket-granting ticket with arbitrary group memberships and a ten-year expiration, allowing continued domain admin access even after all user passwords are reset. Which attack technique does this describe?
- AKerberoasting
- BPass-the-hash attack
- CGolden ticket attack
- DSilver ticket attack
Show answer & explanationAnswer & explanation
Correct answer: C. Golden ticket attack
Forging a TGT using the krbtgt account's hash creates a golden ticket, granting near-unlimited, long-lived access to any resource in the domain regardless of subsequent password changes, since the krbtgt key controls the entire Kerberos trust.
Why the other options are wrong
- A. Kerberoasting cracks service account passwords from requested TGS hashes, not forging a TGT with krbtgt.
- B. Pass-the-hash reuses an NTLM hash for authentication, not Kerberos ticket forgery.
- D. A silver ticket forges a TGS using a service account's hash, granting access to only that specific service, not domain-wide access.
Golden Ticket Attack
A Kerberos attack where an adversary uses the krbtgt account's NTLM hash to forge a Ticket Granting Ticket, granting persistent, domain-wide access that survives password resets.
- Requires the krbtgt hash, often obtained via DCSync
- Grants access to any service in the domain as any user
- Remediated by resetting the krbtgt password twice
Memory trick: Golden ticket = the master key to the whole Kerberos kingdom